Authentication that keeps
good customers moving.
ACS, risk-based authentication, passkeys and in-app approval — layered strong customer authentication that keeps good customers moving. One platform for every authentication moment — from card-not-present challenges to login step-up — tuned so friction lands only where the risk actually is.
Every layer of strong customer authentication.
One platform for the full SCA surface — issuer ACS, risk-based scoring, passkeys, in-app approval and OTP fallback — governed by a single step-up policy engine.
Access Control Server
A full issuer-side ACS that answers 3-D Secure authentication requests for your card portfolio, with per-BIN policy control and scheme-compliant messaging.
Risk-based authentication
Score each authentication on device, behaviour, velocity and transaction context. Authenticate the safe majority silently and reserve challenges for genuine anomalies.
Passkeys & FIDO2
Phishing-resistant passwordless credentials bound to the customer's device. One biometric touch replaces OTPs — stronger security with dramatically less abandonment.
In-app approval
Push a rich approval prompt to your banking app showing merchant, amount and currency. The customer confirms with a fingerprint; the transaction proceeds in seconds.
OTP fallback channels
SMS, email and voice one-time passcodes with rate limiting and delivery failover — dependable coverage for customers without smartphones or app installs.
Step-up policy engine
Compose layered policies: silent for trusted devices, passkey for new ones, in-app approval above a threshold. Change policy in the dashboard, not in a release cycle.
Challenge the risk, not the customer.
QAuth scores every authentication on device, behaviour, velocity and transaction context, then lets the safe majority through silently. Genuine anomalies get a step-up — everyone else keeps moving.
- Signals, not frictionDevice, geo, velocity and behavioural context decide the path before a customer ever sees a prompt.
- Exemptions applied automaticallyTRA, low-value and trusted-beneficiary exemptions used where scope allows, with clean fallback to challenge.
- Tuned from the dashboardAdjust thresholds and channels live — no release cycle to change how customers are authenticated.
Passkeys and in-app approval replace the OTP treadmill.
Bind credentials to the customer's hardware and swap one-time codes for a single biometric touch — stronger security with far less abandonment.
The right challenge, at the right moment.
Event arrives
A payment, login or sensitive action triggers an authentication request into QAuth with full context attached.
Risk engine decides
Your policy and the risk score choose the path: silent pass, passkey, in-app approval or OTP fallback.
Signed result returned
QAuth returns a verifiable authentication result your systems — and the card schemes — can trust and audit.
Start an authentication in a single request.
Send the transaction context; QAuth evaluates policy and risk, then tells you whether to proceed silently or which challenge to render. Every decision returns a signed, verifiable result.
The controls that keep SCA compliant and low-friction.
Exemptions, delegated authentication and full auditability — configured once and enforced everywhere issuers and PSD2/SCA programmes rely on them.
Part of a complete issuer stack.
Q3DS
EMV 3-D Secure authentication for issuers and acquirers, engineered for frictionless flows and regulatory compliance across markets.
Explore Q3DS TokenizationQVault
Network tokenization with push provisioning and a hardened vault — one hub for issuers, one for acquirers and merchants.
Explore QVault IssuingQCard
Full lifecycle management for virtual and physical prepaid programs: issue, load, control, monitor and settle.
Explore QCardRetire the OTP treadmill.
Migrate your portfolio to risk-based, passkey-first customer authentication — silent for the safe majority, strong where it counts.